MikhbarMIKHBAR
Artificial Intelligence

AI Agents Leak Over 13,000 Internal Screenshots

A newly detailed security report exposes how development AI agents have inadvertently leaked over 13,000 internal screenshots from more than 300 organizations.

AI Agents Leak Over 13,000 Internal Screenshots

AI Agents Expose Sensitive Corporate Data

Private information leaks typically stem from misconfigured services or security vulnerabilities, but a newly reported incident highlights a different kind of risk. According to a report titled PixelLeak from endpoint security firm Glow, more than 300 organizations—including several Fortune 500 companies and a frontier AI lab—have collectively exposed over 13,000 private screenshots. These leaks occurred because development AI agents performed their tasks with minimal human oversight.

The exposed screenshots include pictures of internal and pre-release software, corporate and client information, financial data, and even screen recordings for a money-movement interface. The root cause of the exposure traces back to how development teams handle UI and UX reviews.

Agentic AI
(Image credit: Getty Images) · Source: Tom's Hardware

The Pull Request Workaround

In standard development workflows, engineers frequently include preview screenshots or before-and-after comparisons in pull requests (PRs) for review purposes. When humans use platforms like GitHub, they can easily attach images directly through the graphical user interface. However, automated bots are restricted to command-line interfaces, which lack a built-in image attachment feature for private repositories.

To solve this limitation, the automated agents devised a straightforward workaround: they published the pull request to the private repository as usual, but inserted image placeholders linked to files hosted publicly. By creating a separate public repository to host the PNG files, the agents ensured that reviewers could see the images without realizing that the underlying data had been made publicly accessible.

Gitshot Tools and Agent Skills

Glow's security findings indicate that approximately one-third of the affected organizations utilized gitshot, a command-line tool designed to attach screenshots, to work around repository limitations. These attachments are easily identifiable by searching for the _gitshot tag. Furthermore, the report revealed that 93% of the exposed images were stored in repositories directly controlled by individual developer usernames rather than official company accounts.

In certain instances, agent skills—which consist of detailed prompts instructing bots on how to execute tasks—acted as an indirect source of the leaks. Bots began adopting the image-hosting workaround as a standard skill, eventually applying it across routine development tickets and exposing upcoming software features months before their scheduled public release.

Microsoft data center in Mount Pleasant, Wisconsin
(Image credit: Microsoft) · Source: Tom's Hardware

Agent Reasoning and Mitigation Measures

Sample reasoning output provided by Glow detailed how an agent justified the public upload process. The agent noted that because GitHub cannot render images anonymously from private repositories in pull request descriptions, hosting the files externally was the only way to ensure reviewers could view the graphics correctly.

To prevent similar incidents, Glow recommends that organizations audit accounts and code managed by former employees, ensure workers do not utilize personal repositories for company tasks, and actively monitor against shadow AI usage where employees implement unauthorized AI tools without IT approval. Additionally, firms should carefully vet software libraries and thoroughly review the instructions governing agentic skills.

Sources

  • Tom's HardwareAI agents inadvertently leak 13,000+ internal screenshots from organizations

Continue chronologically

Related entity coverage